What's New in 2.15.0
A Redesigned Data Security Experience
Version 2.15.0 introduces a completely redesigned user interface for Data Security, and it's the headline change in this release. Threat Detections, Detection Controls, Data Auditing, and Health Check have all been rebuilt with a modernized, streamlined design that makes it easier to navigate between tools, understand what's happening across your environment at a glance, and get to the actions you need faster.
Workflows in these areas have been reorganized around how you actually work day to day — investigating an event, tuning detection settings, running a query, or checking the health of your detection and audit pipeline should all feel more direct, with cleaner navigation and less hunting for the right screen or button. The visual design has been refreshed throughout to bring a more consistent look and feel across the product, and we're continuing to refine the experience based on customer feedback as the new UI rolls out.
Review the Release Notes below for the current release version, new features, fixed issues, and known issues before planning an installation or upgrade.

Threat Detections
Retain Snapshots
Snapshots taken by a threat detection event can now have their expiry extended directly from the event's own action menu — no need to configure a separate scheduled snapshot ahead of time just to buy more investigation time. Select Take an Action → Retain Snapshots on a Threat Detections event to push out the expiry of every snapshot tied to that event, either to a specific date or by adding an extension interval to the current expiry. This gives you more room to investigate and recover from a threat before those snapshots are purged. The default snapshot expiry applied when an event is first detected is also configurable directly from the UI, in both the old and new GUI. See Retain Snapshots and Snapshot Settings for full details.
Recovery Manager Retention Extended
Recovery Manager's event retention has been significantly extended. User activity for active events is now retained for 120 days, up from the previous default of 7 — so investigations that take longer than a week no longer lose the ability to run Recovery Manager against an archived event. Retention still drops to 3 days once an event is closed, so don't close an event until its data has been recovered. See Data retention and audit cache for full details.
Cyber Recovery Manager for Active Auditor Events
Active Auditor events now support Cyber Recovery Manager, extending the same snapshot-based data recovery workflow used for Ransomware Defender events to Active Auditor triggers (Mass Delete, Data Loss Prevention, and Custom Triggers). See Active Auditor for full details.
Snapshot Reuse and Deduplication
Ransomware Defender and Easy Auditor Active Events now check for a recent, reusable snapshot on the same (or a parent) path before creating a new one, cutting down on redundant PowerScale snapshots when multiple events or users trigger snapshot creation on the same path in quick succession. The reuse window defaults to 60 minutes and is configurable via the rsw_snapshot_reuse_minutes setting. This release also fixes two related issues: reused snapshots weren't always showing up in an event's snapshot list and history, and a snapshot deleted outside of Eyeglass could still be treated as reusable. See Snapshot Settings — Snapshot Reuse and Deduplication for full details.
Detection Controls
Automated Historical Event Ingestion on Upgrade
When upgrading to 2.14.1 or 2.15.0, historical events are now automatically ingested into the Application Fingerprinting learning database as part of the upgrade itself — including events in both the False Positive and Unresolved states. This gives AFP an initial baseline of known-safe behavior drawn from your existing event history, with no manual upload required. See Automatic event ingestion on upgrade to 2.14.1 / 2.15.0 for full details.
Integrations
New Webhook Payload Fields
The Zero Trust webhook payload for Data Security events now includes several new fields in extraParams: alertType (Threat Detection, Threat Hunting, or a reserved value for future Data Attack Surface Manager integration), threatCategory, threatDescription, source, and sourceType. These fields are appended to the existing payload and do not affect existing integrations. See extraParams fields for full details.
See Also
Need Help?
- Contact Support: Reach out to Superna Support for configuration assistance or troubleshooting help.